Data Obfuscation

T1001

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to make the content more difficult to discover or decipher and to make the communication less conspicuous and hide commands from being seen. This encompasses many methods, such as adding junk data to protocol traffic, using steganography, or impersonating legitimate protocols.

Detection rules4

Rules on DetectionCode tagged with T1001 or one of its sub-techniques.

Sigma2

RuleLevelLog sourceTechnique
Suspicious LDAP-Attributes Usedhighwindows / NULLT1001.003
ADSI-Cache File Creation By Uncommon Toolmediumwindows / file_eventT1001.003

Splunk2

RuleTypeRiskData sourceTechnique
Windows PowGoop Beacon DecodingTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2T1001
Windows Suspicious QEMU ExecutionTTPNULLSysmon EventID 1T1001

Sub-techniques3

IDNameExamples
T1001.001Junk Data18
T1001.002Steganography13
T1001.003Protocol or Service Impersonation22

Groups1

Software13

Campaigns1

Procedure examples15

Groups1

Used byProcedure example
GroupGamaredon Group

Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings.

Software13

Used byProcedure example
MalwareDarkGate

DarkGate will retrieved encrypted commands from its command and control server for follow-on actions such as cryptocurrency mining.

Toolevilginx2

evilginx2 can modify the Origin and Referrer fields in HTTPS headers it relays between intended victims and legitimate websites to comply with cross-origin resource sharing (CORS) restrictions.

MalwareFlawedAmmyy

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

MalwareFRAMESTING

FRAMESTING can send and receive zlib compressed data within `POST` requests.

MalwareFunnyDream

FunnyDream can send compressed and obfuscated packets to C2.

MalwareNinja

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

MalwareRDAT

RDAT has used encoded data within subdomains as AES ciphertext to communicate from the host to the C2.

View all 13 software examples

Campaigns1

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4.

References1

  1. Bitdefender FunnyDream Campaign November 2020 Open source
    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.